Perils of living in Massachusetts. I hope similar laws pass federally in the United States.
That being said, I've been on the other side of GDPR. Getting ready for GDPR around 2017 was so much work. We initially had a lengthy confluence runbook with all the places data had to be deleted from. It took a while to automate. Painful, but it's the right thing to do.
RE: OP
I'm pretty sure this is in violation of both GDPR/CCPA
IANAL, but I agree. In my past companies, when a GDPR deletion request comes, we follow through and delete the data. We might ask users to verify their identity but that's about it. It should be 2-3 emails back and forth.
Yeah, 6% is bad but for the shit show, I expected more.
The only way to get people to move is to move yourself. If we start more engaging discussions on the fediverse and make software/engineering improvements to projects (kbin, lemmy, mastodon, native apps), we will get there.